Jerry
not rly active lol
Hi,
So you guys have some problem with revcms??
Oke let we fix the exploit
Find final public function forgotten() (class.users.php) and delete the whole function!
Go to class.core.php and delete everything that looks like this case "forgot":
Yeah you fixed the exploit! Nobody can change your password now!!
How was this could be used (Shame for the big retros)
How to find :By logging everything in your cms ;I Special thanks to Spot Ify
Found by searching into the logs :
And then found this :
He also could use post form to change the password since you guys are stupid to put seckey to NULL or 1234 XD
Owner who destroyed all your things Ricardo ... Owner : weebz.net
Maybe something you guys need to do:
Maybe a like for me, Sir Jamal and Sopt Ify!!
So you guys have some problem with revcms??
Oke let we fix the exploit
Find final public function forgotten() (class.users.php) and delete the whole function!
Go to class.core.php and delete everything that looks like this case "forgot":
PHP:
DELETE :
case "forgot":
$users->forgotten();
break;
DELETE :
case "forgot":
header('Location: '.$_CONFIG['hotel']['url'].'/me');
exit;
break;
Yeah you fixed the exploit! Nobody can change your password now!!
How was this could be used (Shame for the big retros)
How to find :By logging everything in your cms ;I Special thanks to Spot Ify
Found by searching into the logs :
And then found this :
The guy used this to change the password :2014-06-26 16:50:58 ipipipipip POST /forgot - 80 - 141.101.104.219 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+rv:30.0)+Gecko/20100101+Firefox/30.0 __cfduid=d76c81d40ec99160437607c4f5565871b1400161926734;+_ga=GA1.2.817099073.1403220409;+PHPSESSID=642pittqttuv4u692nkhptodh6You must be registered for see links
You must be registered for see links
He also could use post form to change the password since you guys are stupid to put seckey to NULL or 1234 XD
Owner who destroyed all your things Ricardo ... Owner : weebz.net
Maybe something you guys need to do:
Or just make a CMS by your self in php or asp.net (pssht i recomment asp.net its simular to butterfly so then you have 2 fly's in one thing)
And if you cant make a own just read tutorials or just use trail and error
(I made my own cms too ;$ in asp.net and i love it lol)
gr Spot Ify
Maybe a like for me, Sir Jamal and Sopt Ify!!